Nine layers of account defence

Security that keeps important activity visible

No system can remove every threat. AvenQuant combines access controls, encryption, monitoring and human investigation to reduce avoidable risk and help customers respond quickly.

1. Multi-factor authentication

Multi-factor authentication adds a second proof of identity after the password. Customers should use an authenticator method where available, store recovery information safely and never read a one-time code to a caller.

A valid code does not make a request trustworthy. If you did not begin the sign-in, deny it, change your password from a known device and contact support.

2. Encryption and protected information

Transport encryption protects information moving between a supported browser and the service. Sensitive stored records are protected using access-controlled systems appropriate to their purpose.

Encryption cannot protect a password entered on a fraudulent website or information voluntarily sent to an impersonator. Always check the domain before signing in.

3. Anti-fraud monitoring

Monitoring looks for unusual access, rapid profile changes, payment inconsistencies and behaviour that may indicate account takeover. A flagged event can be paused while support verifies it.

Reviews are risk-based and may occasionally delay a legitimate request. They do not imply wrongdoing and are intended to prevent irreversible loss.

4. Login and activity alerts

Alerts can identify a new device, password change or other significant event. Read the full message and reach the service through a saved address rather than following a link in an unexpected message.

Keep your email address and telephone number current so warnings reach you. Report an alert you do not recognise as soon as possible.

5. Device and session controls

Session controls limit how long access remains active and allow current sessions to be reviewed. Sign out on shared devices, remove devices you no longer use and protect your screen with a strong local passcode.

Public Wi-Fi and borrowed computers increase exposure to observation and malicious software. Use a device you control for identity documents and payment activity.

6. Account recovery

Recovery requires enough evidence to reconnect the rightful customer without giving an attacker an easy bypass. Support may ask for updated identity evidence or a secure confirmation through an existing channel.

We do not recover access solely because someone knows public biographical information. Additional review is expected when contact details have recently changed.

7. Restricted integrations and permissions

Where account connections or access keys are available, permissions are limited to the stated function. Use the narrowest scope, remove access that is no longer required and never publish a secret key.

A connection that can view information should not automatically be able to move funds. Review the exact capability before approval.

8. Audit records

Time-stamped records support investigation of sign-ins, setting changes, payment requests and support actions. They help distinguish a market outcome from an account-access problem and provide context for a complaint.

Records are retained according to legal, operational and privacy requirements. Access is limited to staff with a business reason.

9. Incident support

If you suspect compromise, stop communicating with the suspected sender, secure your email account and contact [email protected]. Provide the time and nature of the event without sending passwords or full payment credentials.

Support can guide containment, preserve relevant records and explain next steps. Contact your bank promptly if a payment may have been redirected.

Your part in security

Use a unique password, enable multi-factor authentication and keep software current. Do not install remote-access software at the request of a trading caller, and do not allow anyone to operate your account while watching your screen.

Security controls reduce risk but cannot guarantee that information, funds or investments will never be affected. Market losses are different from security incidents and remain possible even when every control works as intended.